Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
  • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • Podcasts
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
  • Podcasts
Follow US
© 2026 By Crypto Times. All Rights Reserved.
Ethereum News

Mysterious Wallet Drains 326 ETH from Over 570 Ethereum Addresses

Unlike typical "drainer-as-a-service" scams that rely on tricked approvals for ERC-20 tokens, this operation pulled almost exclusively native ETH.

Written By:
Gopal Solanky

Last updated: 40 minutes ago
Published 55 minutes ago
Share
Last updated: 40 minutes ago
Published 55 minutes ago
Mysterious Wallet Drains 326 ETH from Over 570 Ethereum Addresses
Show AI Summary
An Ethereum address drained funds from over 570 wallets within 13 hours, stealing around $760,000 in ETH between April 29 and 30, 2026.
The attacker consolidated stolen ETH before bridging it through THORChain into Bitcoin and Monero, effectively laundering funds across chains.
The operation’s speed and selectivity peaked with 244 wallets emptied in one hour, with private key compromises likely due to leaked credentials from past breaches.

In a sophisticated operation spanning just 13 hours, a single Ethereum address drained funds from more than 570 wallets, making off with approximately 326 ETH worth around $760,000—as per onchain data from Etherscan. 

The incident, which unfolded between April 29 and 30, 2026, has raised fresh concerns about the long-term security of self-custodied crypto assets, particularly older wallets. 

The exploiter address, flagged as Fake_Phishing2831105 on Etherscan, consolidated the stolen ETH before bridging the bulk of it, roughly 324.74 ETH, through THORChain into Bitcoin and Monero, effectively laundering the funds across chains. 

Rapid sweep target mixed wallets

The attack stood out for its speed and selectivity. At its peak, the drainer emptied 244 wallets in a single hour. What puzzled observers was the victim profile. While some wallets had sat dormant for over eight years, others had shown recent activity. A handful had never sent any outgoing transactions at all. 

Unlike typical “drainer-as-a-service” scams that rely on tricked approvals for ERC-20 tokens, this operation pulled almost exclusively native ETH. That signature strongly suggests the attacker possessed the private keys, allowing them to sign transactions directly from the victims’ wallets without any user interaction or malicious smart contract. 

As of now, no widespread phishing campaign or compromised decentralized application has been linked to the incident. Many victims reportedly discovered the losses only after checking their balances, with little to no warning.

Private key compromises likely culprit

Analysts point to leaked credentials as the most plausible explanation. The 2022 LastPass breach, in which encrypted password vaults were stolen, remains a prime suspect. Security researchers have previously tied similar unattributed thefts to offline cracking of those vaults, a process that improves with time and computing power. 

Ethereum Dormant Wallet Drain, April 30, 2026

A wallet labelled by Etherscan as Fake_Phishing2831105 has been receiving funds from many addresses and rapidly moving them through swaps and cross chain infrastructure.

The address is:

0xA707034429c8E4E01df056C0CbCf478F0FBeFAd7… pic.twitter.com/CVqo9mwGAQ

— MASTR (@MastrXYZ) April 30, 2026

Other potential vectors include compromised wallet software, trading bots that require users to input private keys, or supply-chain attacks on development libraries. The mixed age of the drained wallets supports the idea of an aggregated list drawn from multiple historical leaks. 

After the final drain around 12:39 UTC on April 30, they waited several hours before testing small transfers, then executed the large bridge in one transaction. This level of operational discipline is typical of experienced on-chain criminals.

Broader implications for crypto security

The incident serves as a stark reminder that “cold” wallets are not immune to risk if their keys were ever exposed. Forgotten wallets from the ICO era or early DeFi days can become liabilities years later if seeds or private keys were stored insecurely. 

Security professionals recommend generating fresh wallets on hardware devices for any remaining funds and avoiding reuse of older seed phrases. 

As of now, there is no indication of a flaw in Ethereum’s core protocol. The blockchain simply processed validly signed transactions. The vulnerability lies in the persistent human and infrastructure weaknesses that continue to expose keys long after initial compromises. 

This event adds to a growing list of private-key-based thefts that highlight the permanent nature of blockchain transactions: once keys are lost, recovery options are nonexistent. For now, the attacker remains unidentified, and the full scope of compromised credentials may never be publicly known. 

This is a developing story. More information will be updated as the event unfolds. 

Also read: Carrot Becomes First DeFi Casualty of $285M Drift Exploit

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News
Google News Banner

TAGGED:Crypto Hack
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link
Gopal Solanky - Crypto Research Analyst at The Crypto Times
By Gopal Solanky Sr. Crypto Journalist
Follow:
Gopal Solanky is a Research Analyst and Reporter with over 5 years of experience in DeFi, blockchain, crypto, IT, and financial markets. With a Bachelor's in Computer Applications, he brings a strong technical foundation to his analysis and reporting. Gopal focuses on breaking down complex topics for both seasoned investors and curious readers. His work has been referenced by publications like Business Insider and Vulture.com, highlighting his contributions to industry stories around topics like Huwak Tuah Memecoin and the FTX collapse.

Latest News

American Bitcoin's $330M Time Bomb: Every BTC It Has Mined Could Vanish by 2027
American Bitcoin’s $330M Time Bomb: Every BTC It Has Mined Could Vanish by 2027
Tether Posts $1.04B Q1 2026 Profit; Reserve Buffer Hits Record $8.23B
Tether Posts $1.04B Q1 2026 Profit; Reserve Buffer Hits Record $8.23B
Aptos-Based Tapp Exchange Shutdown Raises Fresh DeFi Stability Concerns
Aptos-Based Tapp Exchange Shutdown Raises Fresh DeFi Stability Concerns
Carrot Becomes First DeFi Casualty of $285M Drift Exploit, Shuts Down 30 Days After Hack
Carrot Becomes First DeFi Casualty of $285M Drift Exploit, Shuts Down 30 Days After Hack
South Korean Court Halts FIU Sanctions on Bithumb Amid Crypto Crackdown
South Korean Court Halts FIU Sanctions on Bithumb Amid Crypto Crackdown

Find Us on Socials

You may also like

Arbitrum DAO Starts Vote to Release $71M in Frozen Kelp Hacker ETH to DeFi United

Arbitrum DAO Starts Vote to Release $71M in Frozen Kelp Hacker ETH to DeFi United

Bitmine Doubles Down on Ethereum with Massive $366M Staking Deposit

Bitmine Doubles Down on Ethereum with Massive $366M Staking Deposit 

Today in Crypto Bitcoin at $77K, Institutional Moves, and Major Hack Reports

Today in Crypto: Bitcoin at $77K, Institutional Moves, and Major Hack Reports

Is DeFi Safe $635M Drained in April’s Record-Breaking Attack Wave

Is DeFi Safe? $635M Drained in April’s Record-Breaking Attack Wave

The Crypto Times Logo PNG

Providing real-time, accurate Crypto reporting. Your trusted source for Crypto News and Research.

Stay Updated

All News
Exclusive
Opinions
Learn
Podcasts

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy

Get In Touch

Contact Us
Career

Find Us on Socials

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information